Sensitive Information Disclosure in REST Client for Ruby (rest-client) before 1.7.3

Sensitive Information Disclosure in REST Client for Ruby (rest-client) before 1.7.3

CVE-2015-3448 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

Learn more about our User Device Pen Test.